stophecom / sharrr-svelte

End-to-end encrypted file transfer.
https://www.sharrr.com
MIT License
122 stars 4 forks source link

Bump @sveltejs/kit from 1.5.0 to 1.12.0 #46

Closed dependabot[bot] closed 1 year ago

dependabot[bot] commented 1 year ago

Bumps @sveltejs/kit from 1.5.0 to 1.12.0.

Release notes

Sourced from @​sveltejs/kit's releases.

@​sveltejs/kit@​1.12.0

Minor Changes

  • feat: expose submitter in use:enhance SubmitFunction (#9425)

  • feat: add data-sveltekit-keepfocus and data-sveltekit-replacestate options to links (requires Svelte version 3.56 for type-checking with svelte-check) (#9019)

Patch Changes

  • fix: don't start debugger on 404s (#9424)

  • fix: handle srcset attributes with newline after comma (#9388)

  • fix: allow tsconfig to extend multiple other tsconfigs (#9413)

  • chore: update Undici to 5.21.0 (#9417)

@​sveltejs/kit@​1.11.0

Minor Changes

  • feat: pause on debugger when falling back to full page reload during development (#9305)

  • feat: expose base via $service-worker, make paths relative (#9250)

Patch Changes

  • fix: don't automatically prerender non-SSR'd pages (#9352)

  • fix: use 308 responses for trailing slash redirects, instead of 301s (#9351)

  • fix: remove buggy cookie path detection (#9298)

  • fix: don't prevent beforeNavigate callbacks from running following a cancelled unloading navigation (#9347)

  • fix: persist DOM state on beforeunload (#9345)

  • fix: redirect to path with/without trailing slash when previewing prerendered pages (#9353)

  • fix: avoid FOUC when using CSS modules in dev (#9323)

  • fix: don't skip required parameters after missing optional parameters (#9331)

  • fix: account for server-emitted assets when prerenering (#9349)

  • fix: deal with fast consecutive promise resolutions when streaming (#9332)

  • chore: replace deprecated property access in preparation for TS 5.0 (#9361)

@​sveltejs/kit@​1.10.0

Minor Changes

... (truncated)

Changelog

Sourced from @​sveltejs/kit's changelog.

1.12.0

Minor Changes

  • feat: expose submitter in use:enhance SubmitFunction (#9425)

  • feat: add data-sveltekit-keepfocus and data-sveltekit-replacestate options to links (requires Svelte version 3.56 for type-checking with svelte-check) (#9019)

Patch Changes

  • fix: don't start debugger on 404s (#9424)

  • fix: handle srcset attributes with newline after comma (#9388)

  • fix: allow tsconfig to extend multiple other tsconfigs (#9413)

  • chore: update Undici to 5.21.0 (#9417)

1.11.0

Minor Changes

  • feat: pause on debugger when falling back to full page reload during development (#9305)

  • feat: expose base via $service-worker, make paths relative (#9250)

Patch Changes

  • fix: don't automatically prerender non-SSR'd pages (#9352)

  • fix: use 308 responses for trailing slash redirects, instead of 301s (#9351)

  • fix: remove buggy cookie path detection (#9298)

  • fix: don't prevent beforeNavigate callbacks from running following a cancelled unloading navigation (#9347)

  • fix: persist DOM state on beforeunload (#9345)

  • fix: redirect to path with/without trailing slash when previewing prerendered pages (#9353)

  • fix: avoid FOUC when using CSS modules in dev (#9323)

  • fix: don't skip required parameters after missing optional parameters (#9331)

  • fix: account for server-emitted assets when prerenering (#9349)

  • fix: deal with fast consecutive promise resolutions when streaming (#9332)

  • chore: replace deprecated property access in preparation for TS 5.0 (#9361)

... (truncated)

Commits


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
vercel[bot] commented 1 year ago

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated
sharrr-svelte ✅ Ready (Inspect) Visit Preview 💬 Add your feedback Mar 17, 2023 at 10:07AM (UTC)
socket-security[bot] commented 1 year ago

Socket Security Pull Request Report

Dependency issues detected: If you merge this pull request, you will not be alerted to the instances of these issues again.

📜 Install scripts

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Package Script field Source
@sveltejs/kit@1.12.0 (upgraded) postinstall package-lock.json, package.json via @sveltejs/adapter-auto@1.0.3
Pull request report summary
Issue Status
Install scripts ⚠️ 1 issue
Native code ✅ 0 issues
Bin script shell injection ✅ 0 issues
Unresolved require ✅ 0 issues
Invalid package.json ✅ 0 issues
HTTP dependency ✅ 0 issues
Git dependency ✅ 0 issues
Potential typo squat ✅ 0 issues
Known Malware ✅ 0 issues
Telemetry ✅ 0 issues
Protestware/Troll package ✅ 0 issues
Bot Commands

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of package-name@version specifiers. e.g. @SocketSecurity ignore foo@1.0.0 bar@* or ignore all packages with @SocketSecurity ignore-all

  • @SocketSecurity ignore @sveltejs/kit@1.12.0

Powered by socket.dev

dependabot[bot] commented 1 year ago

Superseded by #49.